Failure to Sanitize host header value on output in the GateManager Web server could allow an attacker to conduct web cache poisoning attacks. This issue affects Secomea GateManager all versions prior to 9.3
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NSecomea Gatemanager 4250
HWSecomeaall versionsSecomea Gatemanager 4250 Firmware
OSSecomeaall versionsSecomea Gatemanager 4260
HWSecomeaall versionsSecomea Gatemanager 4260 Firmware
OSSecomeaall versionsSecomea Gatemanager 8250
HWSecomeaall versionsSecomea Gatemanager 8250 Firmware
OSSecomea< 9.3Secomea Gatemanager 9250
HWSecomeaall versionsSecomea Gatemanager 9250 Firmware
OSSecomeaall versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Related vulnerabilities
CVE-2020-29026CRITICAL9.0PL ✓same product
Path Traversal w Secomea GateManager — odczyt i zapis dowolnych plików
CVE-2020-14510CRITICAL9.8PL ✓same product
Secomea GateManager — zakodowane dane logowania do telnet umożliwiające RCE jako root
CVE-2020-14500CRITICAL10.0PL ✓same product
Przepełnienie bufora w Secomea GateManager — nadpisanie dowolnych danych
CVE-2022-25787HIGH7.5same product
Information Exposure Through Query Strings in GET Request vulnerability in LMM API of Secomea GateManager allo...
CVE-2020-29032HIGH8.4same product
Upload of Code Without Integrity Check vulnerability in firmware archive of Secomea GateManager allows authent...